Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Re: USB drive auditing

Reply
Thread Tools Display Modes

Re: USB drive auditing

 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      03-29-2009
Hello John,

If you have at least one vista/server2008 machine and your clients are XP
or higher, i suggest to use Group policy preferences where you can define
hardware access for all different kind of devices. Administrationis done
with RSAT. The clients must have installed the Client side extensions.

Download and install RSAT on Vista/2008:

RSAT 32bit:
http://www.microsoft.com/downloads/d...displaylang=en

RSAT 64bit:
http://www.microsoft.com/downloads/d...displaylang=en

Then open Control Panele, Programs and features, Turn windows features on
or off, check the tools you like under "Remote Server Administration Tools"

CSE XP 32bit:
http://www.microsoft.com/downloads/d...displaylang=en

CSE XP 64bit:
http://www.microsoft.com/downloads/d...displaylang=en

CSE 2003 32 bit:
http://www.microsoft.com/downloads/d...displaylang=en

CSE 2003 64bit:
http://www.microsoft.com/downloads/d...displaylang=en

CSE Vista 32bit:
http://www.microsoft.com/downloads/d...displaylang=en

CSE Vista 64bit:
http://www.microsoft.com/downloads/d...displaylang=en


Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
> news: .com...
>
>> Hello John,
>>
>> Never heard about. But why not disabling USB ports with GPO and only
>> open it according your policies?
>>
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

> Unfortunately it is necessary to have some devices - printers and
> scanners - which are connected via USB. However I want to ensure USB
> usage is according to policy by preventing users' personal drives and
> dongles being inserted into the systems. Users are already aware of
> this policy, but have been taking advantage of the USB access to bring
> games, emulators (and viruses) onto the systems, and circumvent the
> www whitelist on the server by using their own USB modems. I have been
> asked to devise a solution that will record accesses of this type.
>
> Thanks for the reply.
>



 
Reply With Quote
 
 
 
 
Al Dunbar
Guest
Posts: n/a

 
      03-29-2009
Also, although I do not have the details handy, there is a registry setting
that will prevent the connection of USB-based storage devices, but allow
printers, keyboards, mice, and etc to work. And I think this too can be set
by group policy.

/Al

"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
news: .com...
> Hello John,
>
> If you have at least one vista/server2008 machine and your clients are XP
> or higher, i suggest to use Group policy preferences where you can define
> hardware access for all different kind of devices. Administrationis done
> with RSAT. The clients must have installed the Client side extensions.
>
> Download and install RSAT on Vista/2008:
>
> RSAT 32bit:
> http://www.microsoft.com/downloads/d...displaylang=en
>
> RSAT 64bit:
> http://www.microsoft.com/downloads/d...displaylang=en
>
> Then open Control Panele, Programs and features, Turn windows features on
> or off, check the tools you like under "Remote Server Administration
> Tools"
>
> CSE XP 32bit:
> http://www.microsoft.com/downloads/d...displaylang=en
>
> CSE XP 64bit:
> http://www.microsoft.com/downloads/d...displaylang=en
>
> CSE 2003 32 bit:
> http://www.microsoft.com/downloads/d...displaylang=en
>
> CSE 2003 64bit:
> http://www.microsoft.com/downloads/d...displaylang=en
>
> CSE Vista 32bit:
> http://www.microsoft.com/downloads/d...displaylang=en
>
> CSE Vista 64bit:
> http://www.microsoft.com/downloads/d...displaylang=en
>
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
>> news: .com...
>>
>>> Hello John,
>>>
>>> Never heard about. But why not disabling USB ports with GPO and only
>>> open it according your policies?
>>>
>>> Best regards
>>>
>>> Meinolf Weber
>>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>>> confers no rights.
>>> ** Please do NOT email, only reply to Newsgroups
>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

>> Unfortunately it is necessary to have some devices - printers and
>> scanners - which are connected via USB. However I want to ensure USB
>> usage is according to policy by preventing users' personal drives and
>> dongles being inserted into the systems. Users are already aware of
>> this policy, but have been taking advantage of the USB access to bring
>> games, emulators (and viruses) onto the systems, and circumvent the
>> www whitelist on the server by using their own USB modems. I have been
>> asked to devise a solution that will record accesses of this type.
>>
>> Thanks for the reply.
>>

>
>



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: USB drive auditing Meinolf Weber [MVP-DS] Server Security 0 03-28-2009 10:51 PM
Auditing on a Hard drive Fabio Windows Server 3 01-31-2007 06:48 PM
Re: Auditing Herb Martin Active Directory 0 12-12-2006 03:13 PM
Re: ADAM auditing - EventID 2521 unable to initialize auditing security system Lee Flight Active Directory 0 04-06-2005 03:17 PM
Auditing Peretz Stern Server Security 1 01-07-2005 04:43 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59